In the Linux kernel, the following vulnerability has been resolved:
timekeeping: Adjust the leap state for the correct auxiliary timekeeper
When __do_ajdtimex() was introduced to handle adjtimex for any timekeeper, this reference to tk_core was not updated. When called on an auxiliary timekeeper, the core timekeeper would be updated incorrectly.
This gets caught by the lock debugging diagnostics because the timekeepers sequence lock gets written to without holding its associated spinlock:
WARNING: include/linux/seqlock.h:226 at __do_adjtimex+0x394/0x3b0, CPU#2: test/125 aux_clock_adj (kernel/time/timekeeping.c:2979) __do_sys_clock_adjtime (kernel/time/posix-timers.c:1161 kernel/time/posix-timers.c:1173) do_syscall_64 (arch/x86/entry/syscall_64.c:63 (discriminator 1) arch/x86/entry/syscall_64.c:94 (discriminator 1)) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)
Update the correct auxiliary timekeeper.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 4, 2026 |
| Ubuntu | — | Upgrade linux-image-azure-fdeUpgrade linux-image-oem-24.04bUpgrade linux-image-6.17.0-1019-oracleUpgrade linux-image-azure-fde-6.17Upgrade linux-image-oracle-64k-6.17Upgrade linux-image-oem-6.17Upgrade linux-image-gcp-64k-6.17Upgrade linux-image-oracle-6.17Upgrade linux-image-6.17.0-1021-azureUpgrade linux-image-oracleUpgrade linux-image-gcp-6.17Upgrade linux-image-realtime-hwe-24.04Upgrade linux-image-azureUpgrade linux-image-oem-24.04cUpgrade linux-image-oem-24.04Upgrade linux-image-oem-24.04dUpgrade linux-image-azure-6.17Upgrade linux-image-6.17.0-1021-gcpUpgrade linux-image-realtime-6.17Upgrade linux-image-6.17.0-1021-gcp-64kUpgrade linux-image-6.17.0-1019-oracle-64kUpgrade linux-image-oracle-64kUpgrade linux-image-gcpUpgrade linux-image-gcp-64kUpgrade linux-image-oem-24.04aUpgrade linux-image-6.17.0-1018-azure-fdeUpgrade linux-image-6.17.0-1030-oemUpgrade linux-image-6.17.0-1018-realtime | Jul 21, 2026 | Jul 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub